Privacy and Confidentiality

The journal requires researchers to protect the privacy of research participants and the confidentiality of their personal, clinical, genetic, and other sensitive information throughout the entire research lifecycle.

The 2024 Declaration of Helsinki requires every precaution to be taken to protect participants’ privacy and the confidentiality of their personal information. It also places responsibility for protecting participants’ privacy and confidentiality on researchers rather than on participants themselves.

Privacy and confidentiality must be considered during study design, recruitment, consent, data collection, access, analysis, storage, transfer, sharing, publication, archiving, and disposal.

Privacy and Confidentiality

For the purposes of this policy:

Privacy concerns protection of the individual from unnecessary or inappropriate access to their person, circumstances, communications, records, and personal information.

Confidentiality concerns the obligation of researchers and other authorized persons to protect information entrusted to them and to prevent unauthorized access, use, disclosure, alteration, or loss.

Obtaining informed consent does not remove the researcher’s responsibility to protect privacy and confidentiality.

Data Minimization

Researchers should collect, access, use, and retain only information that is reasonably necessary for the legitimate scientific purposes of the study.

Unnecessary direct identifiers should not be collected or retained merely for convenience.

Where identifiable data are not required for the research purpose, investigators should use appropriately de-identified, coded, pseudonymized, or anonymized information in accordance with the approved protocol and applicable requirements.

Researchers must not describe reversibly coded or pseudonymized data as fully anonymous where re-identification remains reasonably possible.

Identifiable Information

Particular care is required when research involves information that directly or indirectly permits identification of a participant.

Such information may include:

  • names, initials, addresses, telephone numbers, or contact details;
  • dates of birth and other distinctive dates;
  • medical-record, hospital, insurance, or other identification numbers;
  • photographs, videos, voice recordings, or facial images;
  • rare diagnoses or distinctive clinical histories;
  • genetic and genomic information;
  • family relationships and pedigrees;
  • detailed geographic information;
  • combinations of demographic and clinical characteristics capable of identifying an individual.

The risk of identification should be assessed from the combination of available information, not only from the presence or absence of a name.

De-Identification and Coding

Where scientifically appropriate, identifying information should be removed or separated from research data as early as reasonably possible.

Coding or pseudonymization systems should be designed so that the key linking a participant’s identity to research data is protected separately and accessible only to appropriately authorized persons.

De-identification must not be carried out in a way that falsifies, distorts, or materially changes scientifically relevant information.

Where re-identification remains possible, the information must continue to be handled as confidential data.

Access to Research Data

Access to identifiable or sensitive research information should be limited to persons who have a legitimate role in the research and require access for that role.

Research teams should use appropriate safeguards proportionate to the sensitivity of the information, which may include:

  • role-based or otherwise restricted access;
  • secure authentication;
  • appropriately protected electronic systems;
  • secure physical storage;
  • controlled transfer procedures;
  • separation of identifying information from research datasets;
  • documented access or accountability procedures where appropriate.

Researchers remain responsible for confidentiality when data are handled by collaborators, laboratories, statisticians, contractors, repositories, or other authorized third parties.

Storage, Retention and Disposal

Personal and sensitive research information must be stored and retained in accordance with the approved research protocol, participant consent, ethics committee requirements, applicable law, institutional policy, and legitimate scientific or regulatory needs.

Research records should not be retained indefinitely without an appropriate purpose or basis.

When identifiable information is no longer legitimately required, it should be securely destroyed, anonymized, or otherwise managed in accordance with applicable requirements.

Data-retention practices should preserve both participant protection and the ability to verify legitimate research findings where required.

Data Sharing and Secondary Use

Sharing research data does not remove confidentiality obligations.

Before sharing participant-level information, researchers should consider:

  • whether participants were informed about the proposed sharing or secondary use;
  • whether consent permits the proposed use;
  • whether ethics committee approval or an additional determination is required;
  • whether information can be sufficiently de-identified;
  • whether access restrictions or data-use agreements are appropriate;
  • whether the proposed recipient has legitimate authority and adequate safeguards.

Public deposition of identifiable or potentially re-identifiable patient data should not occur merely because open-data practices are encouraged.

The protection of participants takes priority over unrestricted data disclosure.

Pediatric Privacy

Research involving newborns, infants, children, and adolescents requires particular attention to privacy.

Children may have limited ability to understand the long-term implications of disclosure of medical, genetic, developmental, behavioral, or family information.

Researchers should therefore consider not only immediate confidentiality risks but also foreseeable future consequences of disclosure.

Information provided by parents or guardians should also be handled carefully where it concerns the child’s privacy.

As children mature, their own privacy interests and developing autonomy should be respected as appropriate.

Genetic and Family Information

Genetic and genomic data require heightened protection because they may remain identifying even after obvious personal identifiers have been removed and may reveal information about biological relatives.

Researchers should consider risks relating to:

  • re-identification;
  • familial disclosure;
  • unexpected findings;
  • future secondary use;
  • linkage with other datasets;
  • potentially sensitive clinical or hereditary information.

Confidentiality arrangements should reflect the sensitivity and persistence of genetic information.

Clinical Records and Retrospective Research

Access to medical records for retrospective or secondary research must have an appropriate ethical and legal basis.

The fact that information already exists in a hospital record, registry, database, or clinical system does not automatically make it freely available for research.

Where consent is waived, privacy and confidentiality safeguards remain required.

Researchers should use only the information necessary for the approved research purpose and comply with any restrictions imposed by the responsible ethics committee, institution, or applicable regulation.

Photographs and Clinical Images

Clinical photographs, videos, imaging files, pathology images, and other visual material must be assessed for identifying information.

Removing a patient’s name does not necessarily make an image anonymous.

ICMJE states that patients have a right to privacy and that identifying information should not be published without appropriate written consent for publication when identification is possible. It also specifically notes that masking only the eye region in a patient photograph is insufficient protection of anonymity.

Detailed requirements for publication are provided in the journal’s Consent for Publication section.

Information Provided During Consent

Potential participants should receive appropriate information about how their personal information will be collected, used, protected, stored, shared, and, where relevant, used in future research.

The 2024 Declaration of Helsinki requires the informed-consent process to include provisions for protecting privacy and confidentiality.

Consent materials should not promise absolute confidentiality where such a promise cannot realistically or legally be guaranteed.

Where limits to confidentiality exist—for example, lawful reporting obligations or necessary research-integrity investigations—these should be addressed appropriately.

Publication of Research Results

Published manuscripts should ordinarily contain no unnecessary information that permits participant identification.

Authors should remove nonessential identifying details from the manuscript, tables, figures, supplementary materials, and associated files.

ICMJE states that nonessential identifying information should be omitted and that informed consent for publication should be obtained where there is doubt that anonymity can be maintained.

De-identification must not be used to alter scientifically important information in a misleading manner.

Confidentiality Breaches

Researchers should have appropriate procedures for responding to loss, unauthorized access, accidental disclosure, or other breaches involving confidential research information.

Where a breach may materially affect participants, researchers should comply with applicable institutional, ethics committee, legal, and regulatory reporting requirements and take reasonable steps to limit further harm.

A serious privacy or confidentiality breach relevant to a submitted manuscript should be disclosed to the journal where necessary for ethical assessment.

Journal Verification

The journal may request clarification or supporting information when there are concerns regarding:

  • inappropriate inclusion of identifiable participant information;
  • inadequate de-identification;
  • unclear authority to access medical or research records;
  • data sharing inconsistent with consent or ethics approval;
  • inadequate protection of pediatric or genetic information;
  • publication of clinical images without appropriate permission;
  • material privacy or confidentiality breaches.

The journal will not normally request identifiable participant datasets unless such information is strictly necessary and can be handled appropriately.

Where verification can be achieved using redacted, coded, aggregated, or other less identifiable documentation, the journal should prefer the less intrusive option.

Serious unauthorized disclosure of participant information, deliberate concealment of privacy violations, falsification of consent or de-identification procedures, or unethical use of confidential research data may lead to rejection or action under the journal’s Research Misconduct, Editorial Actions, and Corrections and Retractions policies.

ISSN 2181-3353 (Print)
ISSN 2181-3353 (Online)